Solved

Creating domain trusts to access remote shares

Posted on 2012-04-10
6
404 Views
Last Modified: 2012-04-11
Hi Guys,

I've got 2 domains in 2 seperate companies on 2003 and 2008 and have been tasked with creating a trust between them so that the local admins can change permissions on the shares on these domains to allow users from the other domains to access them without having to input their credentials each time. There will be a static VPN between the 2 networks.
I have never set these up before so any basic guides or things to look out for when doing this ? (i.e limitations, patching needed etc)

Thanks
0
Comment
Question by:NotExperts
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 26

Accepted Solution

by:
Leon Fester earned 500 total points
ID: 37826677
Firstly you'll need that VPN configured.
Next test that your DNS resolves correctly and your DNS servers are accessible from the remote network.

From that it's easy to setup the trust.
See previously answered question.
http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_23805633.html

Ports required on your firewall for the trust to work.
http://support.microsoft.com/kb/179442
http://technet.microsoft.com/en-us/library/cc759554(v=ws.10).aspx

All you need to know about trusts.
http://technet.microsoft.com/en-us/library/cc759554(v=ws.10).aspx
0
 

Author Comment

by:NotExperts
ID: 37826937
Thanks,

Do i need to setup a stub zone for each domain in the other domains ?
i.e i have 3 domains to setup trusts for so do i need a DNS stub zone for DomainA in DomainB and DomainC and a stub zone for DomainB in DomainA and DomainC etc ?

Ian
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 26

Expert Comment

by:Leon Fester
ID: 37826944
You can add stub zones, I prefer using conditional forwarders;
http://support.microsoft.com/kb/323380

Even a hosts file entry would work.
0
 
LVL 3

Expert Comment

by:chris-burns
ID: 37831513
I was in the same boat with three domains.

As long as your VPN is setup OK with free, unhindered traffic across the tunnel AND your DNS is set up to resolve correctly you will be good to go. ( Again, i think i would use conditional forwarders rather than stub-zones.)

It is surprisingly easy, our difficulty was to have two exchange servers share the same domain name.
0
 

Author Closing Comment

by:NotExperts
ID: 37836128
That's worked fine. Many Thanks
0

Featured Post

MS Dynamics Made Instantly Simpler

Make Your Microsoft Dynamics Investment Count  & Drastically Decrease Training Time by Providing Intuitive Step-By-Step WalkThru Tutorials.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Suggested Courses

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question